---
id: CVE-2026-92590
title: >-
  Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site
  scripting vulnerability in the Generated Fields feature that disables Twig
  autoescaping and fails to encode cached values
summary: >-
  Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site
  scripting vulnerability in the Generated Fields feature that disables Twig
  autoescaping and fails to encode cached values. Content editors can inject
  malicious Java…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: craftcms
product: cms
affected:
  - cms >= 5.7.0 < 5.10.13
published: '2026-09-16'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:25:55.870'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92590'
references:
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-h9jh-v8vc-m5rp'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/craft-cms-5.7.0-before-5.10.13-stored-xss-via-generated-fields
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00138
epssPercentile: 0.03573
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T02:04:13.074478Z'
ingestedAt: '2026-09-16T22:06:50.929Z'
---

## Overview

Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
